Skip to main content
Bower is built for researchers who handle sensitive data. Every feature, from capture to AI processing, is designed with security, privacy, and data isolation as defaults, not afterthoughts.

Compliance

GDPR

GDPR

Compliant

SOC 2 Type II

SOC 2 Type II

In progress

ISO 27001

ISO 27001

In progress

HIPAA

HIPAA

In progress


Security overview

AES-256 encryption

All data encrypted at rest using AES-256 and in transit via TLS, on every connection.

Workspace isolation

Each workspace’s data is isolated at the data layer, scoped to a single workspace beneath the application so cross-workspace access is blocked before any data is returned.

Audit logging

Every create, update, and delete action is logged with who, what, when, and field-level diffs. Exportable to CSV.

Session management

30-minute inactivity timeout. Revoke all sessions instantly from settings. Token expiry enforced server-side.

Role-based access

Four roles (Owner, Admin, Member, Guest) with strict hierarchy enforced at the API level.

AI data handling

Your content is processed for inference only. Your data is never used to train AI models.

Compliance & data protection

GDPR compliant

Full data subject rights: export, deletion, and portability. Designated Data Protection Officer. 30-day response SLA on all requests.

Australian Privacy Act

Operated by Benenota Pty Ltd (ABN 60 691 836 085), compliant with the Australian Privacy Principles (APPs).

Your data rights

  • Export: download a complete copy of all your personal data as JSON from Settings > Privacy > Export my data
  • Delete: permanently remove your account and all associated data from Settings > Security > Danger Zone
  • Cookie control: choose exactly which cookies Bower uses, changeable at any time from Settings > Privacy
  • DPO contact: reach our Data Protection Officer at [email protected]

Infrastructure & sub-processors

All primary data is hosted on Google Cloud Platform (us-central1). The summary below covers our main infrastructure and AI providers. See the complete sub-processor list for every provider, the data it processes, and its current DPA or BAA status. Restricted mode is a separate HIPAA control: it blocks protected content from providers without a signed BAA.
Your content is sent to these providers for inference only. Your data is not used to train AI models.
Sub-processor list reviewed quarterly. Last reviewed: August 2026. View full list →

Policies & documentation

Data privacy

The full technical breakdown of encryption, workspace isolation, access controls, deletion, and your data rights.

Sub-processors

Complete list of third-party services that process data on behalf of Bower, with current DPA and BAA status.

Cookie policy

What cookies Bower uses, why, and how to control them. Essential vs. analytics categories.

Audit logs

Track every change in your workspace: who did what, when, with field-level diffs.

Password & security

Manage your password, sign-in methods, sessions, and account security settings.

Privacy Policy

Full legal privacy policy covering how we collect, use, store, and protect your personal data.

Terms of Service

Terms governing your use of the Bower platform.

Questions?

If you have security questions, need a DPA, or want to report a vulnerability, contact us: